Denial of Service Vulnerability in OpenSearch Dashboards by Amazon
CVE-2026-75897

8.7HIGH

What is CVE-2026-75897?

A vulnerability in OpenSearch Dashboards allows for improper input validation within the capabilities route handler. This flaw permits the size of the request payload to remain unbounded, potentially enabling remote attackers to execute crafted HTTP requests that can lead to a denial of service. As a result, it is crucial for users of affected versions to apply the latest patches to mitigate any risks associated with this vulnerability.

Affected Version(s)

Amazon OpenSearch Service 1.3 <= 3.5

OpenSearch Dashboards 1.3 <= 3.7.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.